<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSV input, only headers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507399#M86345</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I copied the right prop.conf file to both the indexer and UF, but I'm still getting only the headers.&lt;/P&gt;&lt;P&gt;The data I copied is attached below:&lt;/P&gt;&lt;P&gt;# Version 7.3.4&lt;/P&gt;&lt;P&gt;[splunkd]&lt;BR /&gt;EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;event_message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;[scheduler]&lt;BR /&gt;EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;event_message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;[splunk_web_service]&lt;BR /&gt;EXTRACT-useragent = userAgent=(?P&amp;lt;browser&amp;gt;[^ (]+)&lt;BR /&gt;[user@splunk-indexer apps]$ cat search/local/props.conf&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Forcepoint:email]&lt;BR /&gt;&lt;/SPAN&gt;DATETIME_CONFIG =&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Structured&lt;BR /&gt;description = Forcepoint mail relay&lt;BR /&gt;disabled = false&lt;BR /&gt;pulldown_type = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to copy the app folder from my deployment server to the indexer and then paste it there?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jul 2020 10:09:19 GMT</pubDate>
    <dc:creator>zidoz</dc:creator>
    <dc:date>2020-07-05T10:09:19Z</dc:date>
    <item>
      <title>CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507058#M86285</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured a universal forwarder on Windows server to monitor a folder with csv files.&lt;/P&gt;&lt;P&gt;These files are logs from our mail relay system, so they are being written regularly.&lt;/P&gt;&lt;P&gt;I can see the files in my Splunk Search head, but only the title of the columns, not the data itself&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9436i02E849F5CD5D8292/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk.JPG" alt="splunk.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've configured the sourcetype as CSV, added crcSalt=&amp;lt;SOURCE&amp;gt; to the inputs configuration on the Windows Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea why I'm only getting the headers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 12:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507058#M86285</guid>
      <dc:creator>zidoz</dc:creator>
      <dc:date>2020-07-02T12:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507059#M86286</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223252"&gt;@zidoz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share your props.conf?&lt;/P&gt;&lt;P&gt;Probably the problem is on the props.conf file, where do you have it?&lt;/P&gt;&lt;P&gt;Remember that ingesting csv files, props.conf must be on UF and Indexer (or Heavy Forwarder when present).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 12:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507059#M86286</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-02T12:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507075#M86287</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a props.conf file on the UF under the path below:&lt;/P&gt;&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\default&lt;/P&gt;&lt;P&gt;And I have one on the indexer under:&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which one would you like to see?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 12:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507075#M86287</guid>
      <dc:creator>zidoz</dc:creator>
      <dc:date>2020-07-02T12:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507080#M86288</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223252"&gt;@zidoz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;files in $SPLUNK_HOME/etc/system default cnnot be changed!&lt;/P&gt;&lt;P&gt;this means that you haven't a props.conf.&lt;/P&gt;&lt;P&gt;So download a copy of the csv file and following the guided web procedure [Settings -- Add data] find the correct configuration for you input.&lt;/P&gt;&lt;P&gt;Then copy this pros.conf file on Indexer and on Universal Forwarder, not on default folder: create your own app.&lt;/P&gt;&lt;P&gt;Then restart Splunk on both the systems.&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Extractfieldsfromfileswithstructureddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Extractfieldsfromfileswithstructureddata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 13:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507080#M86288</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-02T13:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507399#M86345</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I copied the right prop.conf file to both the indexer and UF, but I'm still getting only the headers.&lt;/P&gt;&lt;P&gt;The data I copied is attached below:&lt;/P&gt;&lt;P&gt;# Version 7.3.4&lt;/P&gt;&lt;P&gt;[splunkd]&lt;BR /&gt;EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;event_message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;[scheduler]&lt;BR /&gt;EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;event_message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;[splunk_web_service]&lt;BR /&gt;EXTRACT-useragent = userAgent=(?P&amp;lt;browser&amp;gt;[^ (]+)&lt;BR /&gt;[user@splunk-indexer apps]$ cat search/local/props.conf&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Forcepoint:email]&lt;BR /&gt;&lt;/SPAN&gt;DATETIME_CONFIG =&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Structured&lt;BR /&gt;description = Forcepoint mail relay&lt;BR /&gt;disabled = false&lt;BR /&gt;pulldown_type = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to copy the app folder from my deployment server to the indexer and then paste it there?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 10:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507399#M86345</guid>
      <dc:creator>zidoz</dc:creator>
      <dc:date>2020-07-05T10:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507461#M86354</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223252"&gt;@zidoz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you're using the default csv props.conf and should be correct, could you share two or three rows of your file to check the props.conf?&lt;/P&gt;&lt;P&gt;Then you have to copy the props.conf both on UF and Indexers and then restart Spunk on the updated systems, you can copy it manually or using a Deployment server or a Master Node (if you have an Indexers Cluster).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 05:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/507461#M86354</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T05:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508665#M86529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the delayed response, it has been a crazy week.&lt;/P&gt;&lt;P&gt;I've check the props.conf file like you originally suggested - and it seems to work correctly&lt;/P&gt;&lt;P&gt;I copied the file to the UF under:&amp;nbsp;&lt;SPAN&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\forcepoint&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and to the indexer under:&amp;nbsp;$SPLUNK_HOME/etc/apps/search&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk services were restarted on both systems, but the results are the same&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 08:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508665#M86529</guid>
      <dc:creator>zidoz</dc:creator>
      <dc:date>2020-07-12T08:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508666#M86530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223252"&gt;@zidoz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what do you mean when you say: "&lt;SPAN&gt;it seems to work correctly" and "but the results are the same"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it's Ok or not?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, could you share the header and some sample of you data?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 08:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508666#M86530</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-12T08:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: CSV input, only headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508672#M86533</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;When I upload a file manually like you initially suggested, it is being parsed correctly.&lt;/P&gt;&lt;P&gt;But when I read the files from the UF I get only the headers, not the entire data of the file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are some samples (I changes the domain and recipient names for security reasons):&lt;/P&gt;&lt;TABLE width="2380"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="104"&gt;Date &amp;amp; Time&lt;/TD&gt;&lt;TD width="221"&gt;From: Address&lt;/TD&gt;&lt;TD width="460"&gt;Envelope Sender&lt;/TD&gt;&lt;TD width="215"&gt;Sender Name&lt;/TD&gt;&lt;TD width="107"&gt;Sender Domain&lt;/TD&gt;&lt;TD width="121"&gt;Recipient Address&lt;/TD&gt;&lt;TD width="64"&gt;Recipient Domain&lt;/TD&gt;&lt;TD width="64"&gt;Subject&lt;/TD&gt;&lt;TD width="64"&gt;Action&lt;/TD&gt;&lt;TD width="64"&gt;Direction&lt;/TD&gt;&lt;TD width="64"&gt;Black/Whitelisted&lt;/TD&gt;&lt;TD width="64"&gt;Blocked Attachment Ext&lt;/TD&gt;&lt;TD width="64"&gt;Filtering Reason&lt;/TD&gt;&lt;TD width="64"&gt;Lexical Rule&lt;/TD&gt;&lt;TD width="64"&gt;Sender IP&lt;/TD&gt;&lt;TD width="64"&gt;Attachment File Type&lt;/TD&gt;&lt;TD width="64"&gt;Attachment Filename&lt;/TD&gt;&lt;TD width="64"&gt;Emb. Domain&lt;/TD&gt;&lt;TD width="64"&gt;Emb. Full URL&lt;/TD&gt;&lt;TD width="64"&gt;Virus Name&lt;/TD&gt;&lt;TD width="64"&gt;Date&lt;/TD&gt;&lt;TD width="64"&gt;Day of Week&lt;/TD&gt;&lt;TD width="64"&gt;Message Size&lt;/TD&gt;&lt;TD width="64"&gt;Spam Score&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/26/2020 13:46&lt;/TD&gt;&lt;TD&gt;overnightmillionaire@boosts.live&lt;/TD&gt;&lt;TD&gt;14973-1569-206245-3919-a.abc=XXXX.com@mail.boosts.live&lt;/TD&gt;&lt;TD&gt;Mind-Hacks&lt;/TD&gt;&lt;TD&gt;mail.boosts.live&lt;/TD&gt;&lt;TD&gt;a.abc@XXXX.com&lt;/TD&gt;&lt;TD&gt;XXXX.com&lt;/TD&gt;&lt;TD&gt;When Will You Get Your Big Break?&lt;/TD&gt;&lt;TD&gt;Discarded&lt;/TD&gt;&lt;TD&gt;Inbound&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;Spam&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;104.140.84.17&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,bit.ly&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://boosts.live/3zxpsyVNkatoWAUfonYGVLGLyg4Alnq2QXAWdwcL0XxTnd5q,http://boosts.live/6c1499faf76704b7bf.jpg,http://boosts.live/70a1ef0532cd295f74.png,http://boosts.live/R8OtTI9UnRKhxwbKJB64Rl5_LdUjdv0K4DI9zwAZ4z36tME,http://boosts.live/a63b3ec82f405cddb9.jpg,http://boosts.live/e6d3a5f8ceb81257b9.png,http://boosts.live/sJeK_Fs85ipZcsgSXC3QrUo5fZZWPtH36iYMlQd52Z6KP0uk,http://www.boosts.live/9RG3JdpFlY8u4rZ8m1Mqx0H23SKZHqt1eAEPn_XyJkGmA8IB,https://bit.ly/3fMfMKR" target="_blank"&gt;http://boosts.live/3zxpsyVNkatoWAUfonYGVLGLyg4Alnq2QXAWdwcL0XxTnd5q,http://boosts.live/6c1499faf76704b7bf.jpg,http://boosts.live/70a1ef0532cd295f74.png,http://boosts.live/R8OtTI9UnRKhxwbKJB64Rl5_LdUjdv0K4DI9zwAZ4z36tME,http://boosts.live/a63b3ec82f405cddb9.jpg,http://boosts.live/e6d3a5f8ceb81257b9.png,http://boosts.live/sJeK_Fs85ipZcsgSXC3QrUo5fZZWPtH36iYMlQd52Z6KP0uk,http://www.boosts.live/9RG3JdpFlY8u4rZ8m1Mqx0H23SKZHqt1eAEPn_XyJkGmA8IB,https://bit.ly/3fMfMKR&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;26/06/2020&lt;/TD&gt;&lt;TD&gt;Fri&lt;/TD&gt;&lt;TD&gt;12667&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/26/2020 13:46&lt;/TD&gt;&lt;TD&gt;mind-hacks@boosts.live&lt;/TD&gt;&lt;TD&gt;14973-27306-26597-3919-a.abc=XXXX.com@mail.boosts.live&lt;/TD&gt;&lt;TD&gt;Overnight Millionaire&lt;/TD&gt;&lt;TD&gt;mail.boosts.live&lt;/TD&gt;&lt;TD&gt;a.abc@XXXX.com&lt;/TD&gt;&lt;TD&gt;XXXX.com&lt;/TD&gt;&lt;TD&gt;Manifest Your Much Deserved Money Overnight&lt;/TD&gt;&lt;TD&gt;Discarded&lt;/TD&gt;&lt;TD&gt;Inbound&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;Spam&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;104.140.84.17&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,bit.ly&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://boosts.live/6c1499faf8f183a4a5.jpg,http://boosts.live/70a1ef053abaa4625f.png,http://boosts.live/a63b3ec82da286e4f0.jpg,http://boosts.live/e6d3a5f8c9c246ecef.png,http://boosts.live/mgt__Nvn-eVvImYlwKA7wRBeYYkcBB1owT_FG0m7Kbi8qZbs,http://boosts.live/pgSr11AGOuTpb3bhpX69GhdIZXrlC84HYI2kpyEa9x1Ovg3U,http://boosts.live/ubFMXfNq8EFDNT0_01tRGK8FBN-oBf_J8Xh82aZb0pzo7yFa,http://www.boosts.live/lKSG3d5-Rsr99F3D_-YYVKLu-20KxrLx-9IEPwjR4aT0Wp4F,https://bit.ly/3fMfMKR" target="_blank"&gt;http://boosts.live/6c1499faf8f183a4a5.jpg,http://boosts.live/70a1ef053abaa4625f.png,http://boosts.live/a63b3ec82da286e4f0.jpg,http://boosts.live/e6d3a5f8c9c246ecef.png,http://boosts.live/mgt__Nvn-eVvImYlwKA7wRBeYYkcBB1owT_FG0m7Kbi8qZbs,http://boosts.live/pgSr11AGOuTpb3bhpX69GhdIZXrlC84HYI2kpyEa9x1Ovg3U,http://boosts.live/ubFMXfNq8EFDNT0_01tRGK8FBN-oBf_J8Xh82aZb0pzo7yFa,http://www.boosts.live/lKSG3d5-Rsr99F3D_-YYVKLu-20KxrLx-9IEPwjR4aT0Wp4F,https://bit.ly/3fMfMKR&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;26/06/2020&lt;/TD&gt;&lt;TD&gt;Fri&lt;/TD&gt;&lt;TD&gt;12665&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/26/2020 13:47&lt;/TD&gt;&lt;TD&gt;bobbragdon@csoonline.com&lt;/TD&gt;&lt;TD&gt;bounce+427efa.0bdb2c-a.abc=XXXX.com@csoonline.com&lt;/TD&gt;&lt;TD&gt;Bob Bragdon - CSO Virtual Events&lt;/TD&gt;&lt;TD&gt;csoonline.com&lt;/TD&gt;&lt;TD&gt;a.abc@XXXX.com&lt;/TD&gt;&lt;TD&gt;XXXX.com&lt;/TD&gt;&lt;TD&gt;Register now for CSOâ€™s Virtual Conference, The New Risk and Security Landscape&lt;/TD&gt;&lt;TD&gt;Accepted&lt;/TD&gt;&lt;TD&gt;Inbound&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;Spam&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;146.20.191.20&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;csoonline.com,eventscloud.com,eventscloud.com,idg.com,idg.com,eventscloud.com,eventscloud.com,eventscloud.com,eventscloud.com,eventscloud.com,eventscloud.com&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://events.csoonline.com/newriskandsecurity/DO,http://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=open,http://na.eventscloud.com/file_uploads/652bead785b85a67e3d5984dd4a4d709_button_RegNow_blue_MuseoSans.png,http://www.idg.com/idg-privacy-policy/,https://events.idg.com/event-series/the-new-risk-and-security-landscape/speakers/,https://na-admin.eventscloud.com/file_uploads/07fafcf8c1503186a6ce9b105a886998_SecurityNewRiskEmailHeader.jpg,https://na-admin.eventscloud.com/file_uploads/ebc8d3ac1acea5f6fb66b5a495bb4537_New_Risk_Speaker_Strip3.jpg,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=http://events.csoonline.com/newriskandsecurity/DO,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=http://www.idg.com/idg-privacy-policy/,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=https://events.idg.com/event-series/the-new-risk-and-security-landscape/speakers/,https://na.eventscloud.com/emarketing/profile.php?id=9c430fad5a3ddaa0ec3d855c81dd9904fdbff482ef77c1422c6bf377377ac759bb21b12317d7654a4ebbbde94eae06cf-MjAyMC0wMiM1ZWY1ZmM0MTJiY2E2" target="_blank"&gt;http://events.csoonline.com/newriskandsecurity/DO,http://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=open,http://na.eventscloud.com/file_uploads/652bead785b85a67e3d5984dd4a4d709_button_RegNow_blue_MuseoSans.png,http://www.idg.com/idg-privacy-policy/,https://events.idg.com/event-series/the-new-risk-and-security-landscape/speakers/,https://na-admin.eventscloud.com/file_uploads/07fafcf8c1503186a6ce9b105a886998_SecurityNewRiskEmailHeader.jpg,https://na-admin.eventscloud.com/file_uploads/ebc8d3ac1acea5f6fb66b5a495bb4537_New_Risk_Speaker_Strip3.jpg,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=http://events.csoonline.com/newriskandsecurity/DO,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=http://www.idg.com/idg-privacy-policy/,https://na.eventscloud.com/emarketing/go.php?i=776370&amp;amp;e=YXJpay5lbGltZWxlY2hAb3Jib2dyYXBoLmNvbQ==&amp;amp;l=https://events.idg.com/event-series/the-new-risk-and-security-landscape/speakers/,https://na.eventscloud.com/emarketing/profile.php?id=9c430fad5a3ddaa0ec3d855c81dd9904fdbff482ef77c1422c6bf377377ac759bb21b12317d7654a4ebbbde94eae06cf-MjAyMC0wMiM1ZWY1ZmM0MTJiY2E2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;26/06/2020&lt;/TD&gt;&lt;TD&gt;Fri&lt;/TD&gt;&lt;TD&gt;20286&lt;/TD&gt;&lt;TD&gt;-5.09&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/26/2020 13:47&lt;/TD&gt;&lt;TD&gt;mind-hacks@boosts.live&lt;/TD&gt;&lt;TD&gt;14973-1569-180978-3919-a.abc=XXXX.com@mail.boosts.live&lt;/TD&gt;&lt;TD&gt;Overnight Millionaire&lt;/TD&gt;&lt;TD&gt;mail.boosts.live&lt;/TD&gt;&lt;TD&gt;a.abc@XXXX.com&lt;/TD&gt;&lt;TD&gt;XXXX.com&lt;/TD&gt;&lt;TD&gt;Couch Potato Goes from 0 - 7,000/mo&lt;/TD&gt;&lt;TD&gt;Discarded&lt;/TD&gt;&lt;TD&gt;Inbound&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;Spam&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;104.140.84.17&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,boosts.live,bit.ly&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://boosts.live/-8GQVgAXKPy_v03WrGO126ofOreEAAI9MphV_QrOmy4MQlPd,http://boosts.live/6c1499faf9f8427e2d.jpg,http://boosts.live/70a1ef05315be64256.png,http://boosts.live/VU22_58DN9JSppZGa3CJOdmUNmglsoy5WuDki-6tYbc9B__O,http://boosts.live/a63b3ec8251bece5ce.jpg,http://boosts.live/ch6M-mSwL1TYtDMuSd7NugN7mmde8lnbZZBRJYzzwUy1Rmdc,http://boosts.live/e6d3a5f8c0e4fb47bf.png,http://www.boosts.live/QS2gOre3BxvAMAsUNmbQn4n3x04Ly7PerU_GohzHC9p9SIL9,https://bit.ly/3fMfMKR" target="_blank"&gt;http://boosts.live/-8GQVgAXKPy_v03WrGO126ofOreEAAI9MphV_QrOmy4MQlPd,http://boosts.live/6c1499faf9f8427e2d.jpg,http://boosts.live/70a1ef05315be64256.png,http://boosts.live/VU22_58DN9JSppZGa3CJOdmUNmglsoy5WuDki-6tYbc9B__O,http://boosts.live/a63b3ec8251bece5ce.jpg,http://boosts.live/ch6M-mSwL1TYtDMuSd7NugN7mmde8lnbZZBRJYzzwUy1Rmdc,http://boosts.live/e6d3a5f8c0e4fb47bf.png,http://www.boosts.live/QS2gOre3BxvAMAsUNmbQn4n3x04Ly7PerU_GohzHC9p9SIL9,https://bit.ly/3fMfMKR&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;TD&gt;26/06/2020&lt;/TD&gt;&lt;TD&gt;Fri&lt;/TD&gt;&lt;TD&gt;12658&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Sun, 12 Jul 2020 09:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-input-only-headers/m-p/508672#M86533</guid>
      <dc:creator>zidoz</dc:creator>
      <dc:date>2020-07-12T09:04:56Z</dc:date>
    </item>
  </channel>
</rss>

